<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Message rejected .Recevd unexpected 1532714272 byte message! ... in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Message-rejected-Recevd-unexpected-1532714272-byte-message/m-p/338343#M5460</link>
    <description>&lt;P&gt;I am monitor a log file on data source server[IP :172.1.1.100] via UF.then sent it to a middle forwarder(Due to limited network access，I  must need a middle forwarder). then middle forwarder forward it to  cluster indexer.But my indexer did not receive any logs.I'm checked for &lt;CODE&gt;_internal&lt;/CODE&gt;. get the followling error:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;'TcpInputProc’  Message rejected .Recevd unexpected 1532714272 byte message! from src=172.1.1.100:42613 ,Maxinum message allowed:67108864.(::)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;The following is &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and &lt;CODE&gt;outputs.conf&lt;/CODE&gt; on data source server&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;cat /opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/local/inputs.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///data/www/logs/paycloud-app.log]
index=tomcat
sourcetype=tomcat_paycloud-app
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;CODE&gt;cat /opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/local/outputs.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout:indexer1]
server=172.21.1.111:9997
[tcpout]
defaultGroup = indexer1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The following is &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and &lt;CODE&gt;outputs.conf&lt;/CODE&gt; on middle forwarder&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;cat /opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/local/inputs.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[splunktcp://9997]
host=connection_ip
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;CODE&gt;cat /opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/local/outputs.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[indexer_discoverty:master1]
pass4SymmKey=123qwe!@#
master_uri=https://172.21.2.106

[tcpout:group1]
autoLBFrequency = 30
forceTimebasedAutoLB = true
indexerDiscovery = master1
useACK = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Q: I confirmed the network is fully available.But why I do not receive any log?&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2017 01:35:16 GMT</pubDate>
    <dc:creator>xsstest</dc:creator>
    <dc:date>2017-12-13T01:35:16Z</dc:date>
    <item>
      <title>Message rejected .Recevd unexpected 1532714272 byte message! ...</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Message-rejected-Recevd-unexpected-1532714272-byte-message/m-p/338343#M5460</link>
      <description>&lt;P&gt;I am monitor a log file on data source server[IP :172.1.1.100] via UF.then sent it to a middle forwarder(Due to limited network access，I  must need a middle forwarder). then middle forwarder forward it to  cluster indexer.But my indexer did not receive any logs.I'm checked for &lt;CODE&gt;_internal&lt;/CODE&gt;. get the followling error:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;'TcpInputProc’  Message rejected .Recevd unexpected 1532714272 byte message! from src=172.1.1.100:42613 ,Maxinum message allowed:67108864.(::)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;The following is &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and &lt;CODE&gt;outputs.conf&lt;/CODE&gt; on data source server&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;cat /opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/local/inputs.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///data/www/logs/paycloud-app.log]
index=tomcat
sourcetype=tomcat_paycloud-app
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;CODE&gt;cat /opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/local/outputs.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout:indexer1]
server=172.21.1.111:9997
[tcpout]
defaultGroup = indexer1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The following is &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and &lt;CODE&gt;outputs.conf&lt;/CODE&gt; on middle forwarder&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;cat /opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/local/inputs.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[splunktcp://9997]
host=connection_ip
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;CODE&gt;cat /opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/local/outputs.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[indexer_discoverty:master1]
pass4SymmKey=123qwe!@#
master_uri=https://172.21.2.106

[tcpout:group1]
autoLBFrequency = 30
forceTimebasedAutoLB = true
indexerDiscovery = master1
useACK = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Q: I confirmed the network is fully available.But why I do not receive any log?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 01:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Message-rejected-Recevd-unexpected-1532714272-byte-message/m-p/338343#M5460</guid>
      <dc:creator>xsstest</dc:creator>
      <dc:date>2017-12-13T01:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Message rejected .Recevd unexpected 1532714272 byte message! ...</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Message-rejected-Recevd-unexpected-1532714272-byte-message/m-p/338344#M5461</link>
      <description>&lt;P&gt;Does anyone know the answer?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2017 05:57:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Message-rejected-Recevd-unexpected-1532714272-byte-message/m-p/338344#M5461</guid>
      <dc:creator>xsstest</dc:creator>
      <dc:date>2017-12-19T05:57:49Z</dc:date>
    </item>
  </channel>
</rss>

